Lucene search

K
ibmIBMF6764A301BB6951756DC36E0575425C0826808BFB54ADF954CDFB8BE53A28F70
HistoryAug 14, 2019 - 10:57 p.m.

Security Bulletin: Aspera Web Applications (Faspex, Console) and On Demand products are affected by OpenSSL Vulnerability (CVE-2017-7468)

2019-08-1422:57:54
www.ibm.com
13

0.005 Low

EPSS

Percentile

75.4%

Summary

Aspera Web Applications (Faspex, Console) and On Demand products have addressed the following OpenSSL vulnerability.

Vulnerability Details

CVEID:CVE-2017-7468 *DESCRIPTION: ** No CVE description.
CVSS Base Score: 3.1
CVSS Temporal Score: See [Not Applicable](<https://psirt.raleigh.ibm.com/teamworks/Not Applicable>) for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM Aspera Faspex 4.1.0

IBM Aspera Console 3.2.0

IBM Aspera Faspex Server on Demand 3.7.3

Remediation/Fixes

For IBM Aspera (Faspex, Console) the issue can be fixed by downloading the following new versions.

On Demand customers should download a related product release for their On Demand image from the following.

Product VRMF APAR Remediation/First Fix
IBM Aspera Faspex 4.2.0 or Higher None <https://downloads.asperasoft.com/en/downloads/6&gt;
IBM Aspera Console 3.3.0 or Higher None <https://downloads.asperasoft.com/en/downloads/34&gt;

CPENameOperatorVersion
ibm asperaeqany

0.005 Low

EPSS

Percentile

75.4%